Latest CVE Feed
-
8.6
HIGHCVE-2017-9066
In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9065
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9064
In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9063
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-9062
In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9061
In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7433
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the at... Read more
Affected Products : vibe- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9059
The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource consumption) by leveraging improper channel callback shutdown when unmounting an NFSv4 filesystem, aka a "module reference and kernel dae... Read more
Affected Products : linux_kernel- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9058
In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9055
An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read.... Read more
Affected Products : libdwarf- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9054
An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just before it was checked for being in bounds, leading to a heap-based buffer over-read.... Read more
Affected Products : libdwarf- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-9053
An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in a few places in this function).... Read more
Affected Products : libdwarf- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9052
An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure to check a pointer for being in bounds (in a few places in this function) and a failure in a check in dwarf... Read more
Affected Products : libdwarf- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9051
libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.... Read more
Affected Products : libav- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9050
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete f... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9049
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incompl... Read more
Affected Products : libxml2- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9048
libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. At the end of the... Read more
Affected Products : libxml2- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9047
A buffer overflow was discovered in libxml2 20904-GITv2.9.4-16-g0741801. The function xmlSnprintfElementContent in valid.c is supposed to recursively dump the element content definition into a char buffer 'buf' of size 'size'. The variable len is assigned... Read more
Affected Products : libxml2- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9045
The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.... Read more
Affected Products : google_i\/o_2017- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-8769
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion... Read more
Affected Products : whatsapp- Published: May. 18, 2017
- Modified: Apr. 20, 2025